August 10, 2001 NESNIP PRIVACY WORKGROUP HIPAA’s Minimum Necessary Standard Presented by: Mildred L. Johnson, J.D.

Slides:



Advertisements
Similar presentations
SIMPLIFYING PRIVACY: HIPAA PRIVACY STANDARDS AND RESEARCH Angela M. Vieira General Counsel Childrens Hospital and Health Center June 5, 2004.
Advertisements

HIPAA Privacy Practices. Notice A copy of the current DMH Notice must be posted at each service site where persons seeking DMH services will be able to.
Responding to Subpoenas and Law Enforcement Demands for PHI: An Overview Janet A. Newberg Chair, Health Law Section Felhaber Larson Fenlon & Vogt, P.A.
Minimum Necessary Standard Version 1.0
HIPAA Privacy Rule “Standards for Privacy of Individually Identifiable Health Information” 45 CFR 160 and 164* *
1 The HIPAA Privacy Rule and Research This presentation will probably involve audience discussion, which will create action items. Use PowerPoint to keep.
NATIONAL FORUM ON YOUTH VIOLENCE PREVENTION: HIPAA PRIVACY RULE CONSIDERATIONS November 1, 2011 Iliana L. Peters, JD, LLM HHS Office for Civil Rights.
HIPAA – Privacy Rule and Research USCRF Research Educational Series March 19, 2003.
Increasing public concern about loss of privacy Broad availability of information stored and exchanged in electronic format Concerns about genetic information.
P E N N S Y L V A N I A C O A L I T I O N A G A I N S T D O M E S T I C V I O L E N C E P E N N S Y L V A N I A C O A L I T I O N A G A I N S T RAPE HIPAA.
HIPAA Minimum Necessary: Use/Disclosure & Role-based Access  Charlene Dunbar Madonna Rehabilitation Hospital  Sheila Wrobel Nebraska Health System.
NAU HIPAA Awareness Training
1 Louisiana Department of Health and Hospitals Basic HIPAA Privacy Training: Policies and Procedures 01/09/
TM The HIPAA Privacy Rule: Safeguarding Health Information in Research and Public Health Practice Centers for Disease Control and Prevention Beverly A.
 The Health Insurance Portability and Accountability Act of  Federal Law designed to protect sensitive information.  HIPAA violations are enforced.
COMPLYING WITH HIPAA PRIVACY RULES Presented by: Larry Grudzien, Attorney at Law.
Are you ready for HIPPO??? Welcome to HIPAA
Privacy, Security and Compliance Concerns for Management and Boards November 15, 2013 Carolyn Heyman-Layne, Esq. 1.
Health Insurance Portability and Accountability Act (HIPAA)
Health Insurance Portability Accountability Act of 1996 HIPAA for Researchers: IRB Related Issues HSC USC IRB.
HIPAA Compliance Strategies for Employers, METs, MEWAs and Taft Hartley Union Trust Funds The HIPAA Colloquium at Harvard University Presented by: Melissa.
Medical Records in Court: Life after HIPAA North Carolina Conference of Superior Court Judges, October 2003 Presented by Jill Moore, UNC School of Government.
HIPAA Health Insurance Portability & Accountability Act of 1996.
Health Insurance Portability and Accountability Act (HIPAA)
HIPAA PRIVACY AND SECURITY AWARENESS.
HIPAA The Privacy Rule Health Insurance Portability and Accountability Act of 1996 (HIPAA) The 104 th Congress passed the Act, Public Law ,
1 Disclosures © HIPAA Pros 2002 All rights reserved.
1 HIPAA OVERVIEW ETSU. 2 What is HIPAA? Health Insurance Portability and Accountability Act.
Computerized Networking of HIV Providers Workshop Data Security, Privacy and HIPAA: Focus on Privacy Joy L. Pritts, J.D. Assistant Research Professor Health.
HIPAA – How Will the Regulations Impact Research?.
NE SNIP PRIVACY WORKGROUP Use and Disclosure of Protected Health Information Regarding a Deceased Individual.
HIPAA Michigan Cancer Registrars Association 2005 Annual Educational Conference Sandy Routhier.
HIPAA Workforce Training PRIVACY and HIPAA MANDATORY Completion of training is mandatory under HIPAA for the entire workforce of the MHRB Including volunteers,
Practicing In Harmony with HIPAA The views and opinions expressed in the presentation are those of the presenter, and not necessarily official positions.
HIPAA SURVIVAL SKILLS: An Update University of Miami1 Marisabel Davalos, M.S.Ed., CIP Associate Director of Educational Initiatives November, 2008.
Health Insurance Portability and Accountability Act (HIPAA) CCAC.
Health Insurance Portability and Accountability Act of 1996 HIPAA Privacy Training for County Employees.
HIPAA BASIC TRAINING Presented by Anderson Health Information Systems, Inc.
HIPAA PRACTICAL APPLICATION WORKSHOP Orientation Module 1B Anderson Health Information Systems, Inc.
Rhonda Anderson, RHIA, President  …is a PROCESS, not a PROJECT 2.
HIPAA Privacy Rules: What Are Plan Sponsors Required to Do?
Health Insurance portability and Accountability Act (HIPAA)‏
1 Privacy Plan of Action © HIPAA Pros 2002 All rights reserved.
HIPAA Training Workshop #1 Council of Community Clinics – San Diego February 7, 2003 by Kaye L. Rankin Rankin Healthcare Consultants, Inc.
HIPAA Privacy Rule Implementation Status Report Richard M. Campanelli, J.D. Director, Office for Civil Rights Before the The Tenth National HIPAA Summit.
HIPAA Overview Why do we need a federal rule on privacy? Privacy is a fundamental right Privacy can be defined as the ability of the individual to determine.
PwC Issues in HIPAA Research Compliance William R. Braithwaite, MD, PhD “Dr. HIPAA” HIPAA Summit 6 Washington, DC 27 March 2003.
HIPAA TRIVIA QUEST December Edition. I’ll ask the questions - and you’ll give the answers.
WHAT GUARDIANSHIP ATTORNEYS SHOULD KNOW BY RACHEL ANNE BROOKS MARCH 15, 2016 Health Care Privacy.
HIPAA Training. What information is considered PHI (Protected Health Information)  Dates- Birthdays, Dates of Admission and Discharge, Date of Death.
Health Insurance Portability and Accountability Act (HIPAA) © 2013 Project Lead The Way, Inc.Principles of Biomedical Science.
Final HIPAA Privacy Rule: The Research Provisions Julie Kaneshiro DHHS Office for Human Research Protections Phone: Fax:
HIPAA Training Workshop #2 Trainer: Kaye L. Rankin Rankin Healthcare Consultants, Inc.
Juvenile Legislative Update 2013 Confidential Records and Protected Disclosures.
Health Insurance Portability and Accountability Act
The HIPAA Privacy Rule: Implications for Medical Research
HIPAA Administrative Simplification
HOGAN & HARTSON, L.L.P. “Publications” “Health”
Permitted Uses & Disclosures of PHI
Health Insurance Portability and Accountability Act
HIPAA Pros - Disclosures
Confidential Records and Protected Disclosures
Disability Services Agencies Briefing On HIPAA
HIPAA Pros - Minimum Necessary
The HIPAA Privacy Rule and Research
National Congress on Health Care Compliance
The Health Insurance Portability and Accountability Act
Issues in HIPAA Research Compliance
Research Compliance: The Research/Privacy Nexus
Presentation transcript:

August 10, 2001 NESNIP PRIVACY WORKGROUP HIPAA’s Minimum Necessary Standard Presented by: Mildred L. Johnson, J.D.

GENERAL RULE Implement reasonable procedures to ensure that only the minimum necessary of protected health information (PHI) is USED, DISCLOSED OR REQUESTED when conducting payment activities and health care operations.

APPLICABILITY Covered Entities Healthcare providers Health insurers Clearing houses Uses, Disclosures and Requests Payment and Healthcare Operations Activities where authorizations are required

EXCEPTIONS Treatment of the Individual Permitted or Required Disclosures to the Individual Pursuant to the Individual’s authorization Disclosures to the Secretary of HHS for compliance and enforcement purposes

EXCEPTIONS Disclosures Required by Law: Public Health Activities Abuse, Neglect or Domestic Violence to the extent authorized by statute or regulation Health Oversight Activities Excludes Private Accreditation Organizations Judicial & Administrative Proceedings Law Enforcement Purposes

USE STANDARDS Identify persons (or classes of persons) in the workforce who need to access PHI to carry out their duties. Identify the categories of PHI to which access is needed and any conditions appropriate to such access. Make reasonable efforts to limit access by those identified above to PHI that they do not need to carry out their duties. No case-by-case review ever required for USE.

USE STANDARD CHECKLIST  Identify and classify all employees & contractors who need access to PHI  Identify the PHI each can access  Provide justification for those allowed access to entire PHI  Identify the conditions when certain PHI is accessible.  Job Descriptions identify access levels

DISCLOSURE AND REQUESTS ROUTINE Requires policies and procedures, which may be standardized protocols. NON-ROUTINE Establish criteria to limit PHI to that reasonably necessary to accomplish the purpose. Individual review using the criteria.

DISCLOSURE STANDARDS Routine v. Non-Routine Disclosures. Reasonable Reliance For Requests Made by: Public Officials Another Covered Entity Professional member of workforce/business associate Researcher (IRB/Privacy Board)

DISCLOSURE: REASONABLE RELIANCE Representation that PHI requested is the minimum amount necessary. Who Public Officials Professional in the Workforce or B.A. Written v. Oral Tracking System

DISCLOSURE: REASONABLE RELIANCE Researchers Requires Written IRB/Privacy Board determination Must describe PHI Must include voting procedures Review Preparatory to Research or for research on PHI of decedents. Copy of death certificate Documentation from researcher Necessity Minimum Necessary

DISCLOSURE CHECKLIST  Identify PHI not subject to an exception or reasonable reliance  Identify individuals/entities that would request PHI  Identify conditions that would apply for disclosure.  Justification for routine disclosures of entire PHI

DISCLOSURE CHECKLIST  Written criteria to limit non- routine disclosure of PHI to that reasonably needed.  Designate individual(s) to review non-routine disclosures.  Written tracking process for each non-routine disclosure reviewed.

REQUEST Applies to Requests made by covered entities to covered entities Key Items Burden is on the requesting party Recipient can use the reasonable reliance standard when disclosing PHI to the requesting covered entity. Routine v. Non-routine

REQUEST CHECKLIST  Identify individual(s) responsible for making requests.  Identify routine requests  Justification for requests requiring the entire medical record.  Designated individual(s) responsible for making determinations of minimal necessary for non-routine requests.